Skip to content
REDMAW

Attack Library

Attack Library

A technical reference for the attacks RedMaw validates: how they work, what they reach and how adversarial validation proves them.

Attack LibraryAI Systems

Training-Data Extraction

A model can repeat what it was shown. That includes what it should not have been shown.

Attack LibraryAI Systems

Tool-Call Injection

The model was asked to summarize a document. The document had other ideas.

Attack LibraryAI Systems

System-Prompt Extraction

The instructions were never secret. They were merely unstated.

Attack LibraryInternal Infrastructure

Unconstrained Delegation

One over-trusted host collects credentials from everyone who visits it.

Attack LibraryInternal Infrastructure

DCSync

The directory is asked to replicate. It has no reason to refuse.

Attack LibraryInternal Infrastructure

ADCS Certificate Abuse

A certificate authority that will issue a certificate for anyone is an identity provider for attackers.

Attack LibraryInternal Infrastructure

NTLM Relay

The credential is never cracked. It is simply forwarded somewhere it still works.

Attack LibraryInternal Infrastructure

AS-REP Roasting

An account setting chosen for convenience becomes an offline attack opportunity.

Attack LibrarySaaS & Identity

Session-Token Replay

Authentication already happened. The token is the proof, and proof can be copied.

Attack LibrarySaaS & Identity

Cross-Tenant Integration Pivot

The boundary on the architecture diagram is not always the boundary in the token.

Attack LibraryAI Systems

RAG / Context Poisoning

If you can influence what gets retrieved, you can influence what the system does with it.

· 6 min read
Attack LibrarySaaS & Identity

SAML Assertion Forgery

Single sign-on concentrates trust. A broken assertion boundary concentrates the damage.

Attack LibraryApplications

Subdomain Takeover

The domain still belongs to you. What answers on it may not.

Attack LibraryApplications

Mass Assignment

The endpoint worked as written. It was written to trust too much.

Attack LibraryApplications

JWT Algorithm Confusion

The token verified. That is not the same as the token being trustworthy.

Attack LibraryApplications

Insecure Deserialization

The defect is not the format. It is that the server trusts attacker-controlled object state.

Attack LibraryApplications

SSRF to Cloud Metadata

The interesting part is not that the application made an unexpected request. It is where that request could reach.

Attack LibrarySaaS & Identity

OAuth Token Abuse

Tokens survive password resets. A stale grant is standing access with no owner watching it.

· 7 min read
Attack LibraryAI Systems

Indirect Prompt Injection

The attacker never talks to the model. The content the model reads does it for them.

· 7 min read
Attack LibraryApplications

BOLA: Broken Object Level Authorization

Authentication proves who is calling. BOLA is what happens when nothing checks what they are allowed to touch.

· 6 min read
Attack LibraryInternal Infrastructure

Kerberoasting

Any domain account can ask for the tickets. The weakness is the password behind the service account.

· 6 min read

Stop assuming you are secure. Prove it.

Continuously test what an attacker can actually reach across your applications, SaaS identities, internal infrastructure and AI systems.